IP Library Patent Application 11867750
Patent Application
App. No. 11/867,750

METHODS AND SYSTEMS FOR USER AUTHORIZATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/867,750
Abstract

A method for controlling access to a system is provided. The method includes creating a role tree including a plurality of privileges, creating a resource tree including a plurality of resources, assigning at least one role for at least one resource to a user, and evaluating the plurality of privileges of the user for a requested service access based on at least one of a user role assignment, a user resource assignment, and a location of a device used by the user to request the service access.

Claims (43)

1 . A method for controlling access to a system, said method comprising:

creating a role tree including a plurality of privileges;

creating a resource tree including a plurality of resources;

assigning at least one role for at least one resource to a user; and

evaluating the plurality of privileges of the user for a requested service access based on at least one of a user role assignment, a user resource assignment, and a location of a device used by the user to request the service access.

2 . A method in accordance with claim 1 wherein creating a role tree further comprises:

storing a hierarchy of privileges; and

forming a role including at least one privilege.

3 . A method in accordance with claim 2 wherein forming a role further comprises grouping at least one of other roles stored in the role tree and a combination of roles and privileges.

4 . A method in accordance with claim 1 wherein creating a resource tree further comprises:

storing a hierarchy of the plurality of resources and a plurality of resource types; and

assigning a resource operation to one of a role and a privilege relating to the operation.

5 . A method in accordance with claim 1 further comprising determining the location of the device used by the user based on at least one of a name of the device used by the user and a set of positioning coordinates.

6 . A method in accordance with claim 1 wherein evaluating the plurality of privileges of the user for a requested service access further comprises:

loading the plurality of privileges of the user into a server memory;

transmitting a secure key and a request to access a service to a server; and

comparing at least one of a user role assignment and a user resource assignment against at least one of a required role and a required privilege for the requested service for the requested resource.

7 . A method in accordance with claim 1 further comprising injecting an authorization method execution path into a method execution path of the requested service access.

8 . A method for authorizing user access to a system, said method comprising:

assigning the user to at least one role for at least one resource, the at least one role chosen from a role tree and the at least one resource chosen from a resource tree;

determining a user's role assignment, a user's resource assignment, and a user location; and

evaluating the user's role assignment, the user's resource assignment, and the user location against at least one of a required role and a required privilege for a requested service for a requested resource.

9 . A method in accordance with claim 8 wherein assigning the user to at least one role for at least one resource further comprises:

storing a plurality of privileges; and

creating a role tree by grouping at least one privilege to form a role.

10 . A method in accordance with claim 9 wherein creating a role tree further comprises creating a role tree by grouping at least one of other roles stored in the role tree and a combination of roles and privileges.

11 . A method in accordance with claim 8 wherein assigning the user to at least one role for at least one resource further comprises:

storing a plurality of resources and resource types; and

creating a resource tree.

12 . A method in accordance with claim 8 wherein determining a user's role assignment, a user's resource assignment, and a user location further comprises at least one of reading a physical name of a device used by the user and reading a set of positioning coordinates of the device used by the user.

13 . A method in accordance with claim 8 further comprising injecting an authorization method execution path into a method execution path of the requested service.

14 . A role and resource based authorization and authentication system comprising:

at least one user device; and

at least one server communicatively coupled to said at least one user device, said at least one server comprising a role tree and a resource tree, said at least one server configured to:

store a set of privileges for a user, the set of privileges based on a user assignment to at least one role for at least one resource;

compare the set of privileges for the user and a user location to a set of required privileges and a location required to access a requested service for a requested resource; and

one of grant and deny access to the requested service for the requested resource based on the comparison.

15 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said at least one user device further comprises a physical name, said at least one user device configured to communicate the physical name to said at least one server.

16 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said at least one user device further comprises a GPS module, said at least one user device configured to communicate a set of GPS coordinates to said at least one server.

17 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said role tree further comprises a plurality of privileges and a plurality of roles, each role of said plurality of roles formed by at least one of a set of privileges of said plurality of privileges and at least one other role of said plurality of roles.

18 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said resource tree further comprises a plurality of resources and a plurality of resource types.

19 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said at least one server is further configured to inject an authorization method execution path into a method execution path for the requested service.

20 . A role and resource based authorization and authentication system in accordance with claim 14 wherein said at least one user device and said at least one server are configured to securely communicate using a token exchange protocol, and wherein the set of privileges for the user is loaded into a server memory to facilitate reducing network traffic between said at least one user device and said at least one server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2010
From: GE FANUC AUTOMATION NORTH AMERICA, INC.
To: GE INTELLIGENT PLATFORMS, INC.
Reel/Frame 024196/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2007
From: SAGE, PETER; ELUMALAI, CHANDRAN; GENDRON, ROBERT
To: GE FANUC AUTOMATION NORTH AMERICA, INC.
Reel/Frame 019925/0013 →